NIST Control Families Flashcards

1
Q

AC

A

Access Control

Account mgmt, access enforcement into and within system, separation of duties, least privilege, logons, remote access, wireless access, mobile device access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AT

A

Awareness Training

Role-appropriate security awareness training, training records.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AU

A

Audit and Accountability

Log events, analyze logs, protect logs, ensure non-repudiation of logs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CA

A

Security assessment and authorization

Assessment plan, pen testing, assessments, POA&M, OA authorization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

CM

A

Configuration Management

Baseline and configuration management, inventory, sw installation and usage restrictions (licensing).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CP

A

Contingency planning

Backup and restore, alternate sites.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IA

A

Identification and authentication

Technical controls. User and device identification (ex: RADIUS).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IR

A

Incident response

IR planning, training, testing, incident handling, incident reporting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

MP

A

Media protection

Media marking, transport, sensitization and use policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

PE

A

Physical and environmental protection

Guards, guns and gates. Emergency power, fire protection, temperature control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

PL

A

Security planning

SSP, SECONOPS, info sec architecture,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

PM

A

Program management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

PS

A

Personnel security

Administrative controls. Position risk, screening, terminations, NDAs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

RA

A

Risk assessment

Security categorization, risk assessments, vulnerability scanning, technical surveillance countermeasures survey.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SA

A

System and services acquisition

Administrative controls. Adequate budgeting, software development life cycle, sw engineering principles, acquisition process, supply chain protection, external developer services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SC

A

System and communications protection

Technical controls. Firewalls, PKI management, VOIP, DNS, ARP, application partitioning, security function isolation, denial of service protection, data transmission confidentiality, honeypots, WIFI transmission protection, port access.

17
Q

SI

A

System and information integrity

Technical controls. Patches, anti-malware, anti-spam, IDS, alerting, detect unauthorized changes, data input validation, error handling.

18
Q

MA

A

Maintenance

Administrative controls. Controlled maintenance, management of tools, vendor maintenance, maintenance personnel

19
Q

ISC2

A

International Information System Security Certification Consortium